forked from blockchain-maxis/signet
-
Notifications
You must be signed in to change notification settings - Fork 0
166 lines (132 loc) · 4.56 KB
/
Copy pathci.yml
File metadata and controls
166 lines (132 loc) · 4.56 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
name: CI
on:
push:
branches: [main]
pull_request:
jobs:
docs:
name: docs links · env · scripts
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: 22
# Fails on broken relative links/anchors, env vars out of lockstep with
# .env.example, and pnpm/cargo script names cited in markdown that do not
# exist. No install step — pure Node stdlib, well under 60s.
- name: Check docs drift
run: node scripts/check-docs.mjs
web:
name: lint • typecheck • test • build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6.0.9
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Lint
run: pnpm lint
- name: Typecheck
run: pnpm typecheck
- name: Test
run: pnpm test
- name: Build
run: pnpm build
contracts:
name: soroban contract tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
with:
targets: wasm32v1-none
- name: Cache cargo
uses: actions/cache@v6
with:
path: |
~/.cargo/registry
~/.cargo/git
packages/contracts/target
key: cargo-${{ hashFiles('packages/contracts/Cargo.lock') }}
- name: Test
working-directory: packages/contracts
run: cargo test
- name: Build wasm
working-directory: packages/contracts
run: cargo build --target wasm32v1-none --release
# Guardrail against accidental contract bloat — a heavy dependency, a
# broken release profile (opt-level/lto/strip), or unbounded logic can
# balloon the deployment artifact. identity-registry is ~9 KB today; the
# 20 KB budget leaves headroom for planned growth while still catching a
# regression. Bump BUDGET_BYTES deliberately when a size increase is
# expected and justified.
- name: Wasm size budget
working-directory: packages/contracts
env:
BUDGET_BYTES: 20480
run: |
wasm="target/wasm32v1-none/release/identity_registry.wasm"
if [ ! -f "$wasm" ]; then
echo "::error::Expected wasm not found at $wasm"
exit 1
fi
size=$(wc -c < "$wasm")
echo "identity_registry.wasm: ${size} bytes (budget ${BUDGET_BYTES} bytes)"
if [ "$size" -gt "$BUDGET_BYTES" ]; then
echo "::error::Contract wasm ${size} bytes exceeds budget ${BUDGET_BYTES} bytes"
exit 1
fi
e2e:
name: e2e smoke tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6.0.9
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Cache Playwright browsers
uses: actions/cache@v6
id: pw-cache
with:
path: ~/.cache/ms-playwright
key: playwright-chromium-${{ hashFiles('apps/web/package.json') }}
- name: Install Playwright browsers
if: steps.pw-cache.outputs.cache-hit != 'true'
run: pnpm --filter @signet/web exec playwright install --with-deps chromium
- name: Install Playwright browser deps (cached hit)
if: steps.pw-cache.outputs.cache-hit == 'true'
run: pnpm --filter @signet/web exec playwright install-deps chromium
- name: Build web app
run: pnpm --filter @signet/web build
- name: Run e2e smoke tests
run: pnpm --filter @signet/web test:e2e
security:
name: dependency audit
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6.0.9
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- name: Install dependencies
run: pnpm install --frozen-lockfile
# Advisory for now (does not fail the build) — flip to blocking once the
# tree is clean. Tighten the level to `moderate` as you triage.
- name: pnpm audit
run: pnpm audit --audit-level high || true
- uses: dtolnay/rust-toolchain@stable
- name: cargo audit
run: |
cargo install cargo-audit --locked || true
(cd packages/contracts && cargo audit) || true